SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-85788

MEDIUM · CVSS 5.5 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The mutable SQL detector component in Amazon's awslabs mysql-mcp-server has an incomplete list of disallowed inputs, potentially allowing context-dependent actors to bypass read-only restrictions and access file-read and file-write SQL sinks through SQL inline comments. This vulnerability could lead to unauthorized data manipulation or exposure. Organizations using this component should prioritize upgrading to version 1.0.23 to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85788
Severity
MEDIUM
CVSS
5.5
EPSS
0.13%

Original NVD Description

Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via SQL inline comments that the regex engine does not treat as whitespace. To remediate this issue, users should upgrade to version 1.0.23.